← All posts
API Gateway, Lambda and Cognito: login from the CLI
Working notes on securing an API Gateway + Lambda endpoint with Amazon Cognito: logging in from the CLI and with plain curl, plus the references that helped.
From the archive · a 2021 working note, kept for reference.
Log in from the command line
aws cognito-idp admin-initiate-auth --user-pool-id <region>_<pool-id> --client-id <app-client-id> --auth-flow ADMIN_NO_SRP_AUTH --auth-parameters USERNAME=myusername,PASSWORD=mypassword
Log in with curl directly
curl -X POST --data @user-data.json \
-H 'X-Amz-Target: AWSCognitoIdentityProviderService.InitiateAuth' \
-H 'Content-Type: application/x-amz-json-1.1' \
https://cognito-idp.<just-replace-region>.amazonaws.com/
The JSON file user-data.json:
{"AuthParameters" : {"USERNAME" : "myusername", "PASSWORD" : "mypassword"}, "AuthFlow" : "USER_PASSWORD_AUTH", "ClientId" : "<app-client-id>"}
References
- Video walkthrough (YouTube)
- How to secure Microservices on AWS with Cognito, API Gateway, and Lambda (freecodecamp.org)
- auth-api-demo/aws-setup.md at master · csepulv/auth-api-demo (github.com)
- Building fine-grained authorization using Amazon Cognito, API Gateway, and IAM | AWS Security Blog
- Event-driven Serverless Architectures with AWS Lambda, SQS, DynamoDB, S3, and API Gateway | LaptrinhX
First published on tanldt.blogspot.com on Jun 11, 2021.